|
按键精灵 2014.05.17762 版
Environment = 1366x768|32|Windows 10 Enterprise
Type = 0xC0000005
Address = 0x48D152
LineNum = 0(0)
Registers:
EAX=FFFFFFFF EBX=00000000 ECX=063E3828 EDX=FFFFFFFF
ESI=063E52C4 EDI=063E52C0 ESP=0019DA94 EBP=0019DC14
Current Modules:
==>
Name = 按键精灵2014.exe, Base = 0x400000, Top = 0x1179000, Size = 14127104
Name = ntdll.dll, Base = 0x77A70000, Top = 0x77C0A000, Size = 1679360
Name = KERNEL32.DLL, Base = 0x77610000, Top = 0x776F0000, Size = 917504
Name = KERNELBASE.dll, Base = 0x77340000, Top = 0x7753C000, Size = 2080768
Name = comctl32.dll, Base = 0x74170000, Top = 0x7437F000, Size = 2158592
Name = msvcrt.dll, Base = 0x75430000, Top = 0x754EF000, Size = 782336
Name = combase.dll, Base = 0x76390000, Top = 0x76606000, Size = 2580480
Name = ucrtbase.dll, Base = 0x77860000, Top = 0x7797F000, Size = 1175552
Name = RPCRT4.dll, Base = 0x777A0000, Top = 0x7785B000, Size = 765952
Name = SspiCli.dll, Base = 0x75240000, Top = 0x75260000, Size = 131072
Name = CRYPTBASE.dll, Base = 0x75230000, Top = 0x7523A000, Size = 40960
Name = bcryptPrimitives.dll, Base = 0x753D0000, Top = 0x7542F000, Size = 389120
Name = sechost.dll, Base = 0x76610000, Top = 0x76686000, Size = 483328
Name = GDI32.dll, Base = 0x757D0000, Top = 0x757F1000, Size = 135168
Name = win32u.dll, Base = 0x756F0000, Top = 0x75707000, Size = 94208
Name = gdi32full.dll, Base = 0x75860000, Top = 0x759BA000, Size = 1417216
Name = msvcp_win.dll, Base = 0x76BF0000, Top = 0x76C6C000, Size = 507904
Name = USE**.dll, Base = 0x754F0000, Top = 0x75687000, Size = 1667072
Name = IMM32.DLL, Base = 0x76310000, Top = 0x76335000, Size = 151552
Name = ADVAPI32.dll, Base = 0x76720000, Top = 0x76799000, Size = 495616
Name = winmm.dll, Base = 0x72AD0000, Top = 0x72AF4000, Size = 147456
Name = winmmbase.dll, Base = 0x72870000, Top = 0x72893000, Size = 143360
Name = cfgmg**.dll, Base = 0x775C0000, Top = 0x775FB000, Size = 241664
Name = MSIMG32.dll, Base = 0x71760000, Top = 0x71766000, Size = 24576
Name = COMDLG32.dll, Base = 0x75710000, Top = 0x757C0000, Size = 720896
Name = shcore.dll, Base = 0x77980000, Top = 0x77A04000, Size = 540672
Name = SHLWAPI.dll, Base = 0x75810000, Top = 0x75854000, Size = 278528
Name = SHELL32.dll, Base = 0x75D90000, Top = 0x7630A000, Size = 5742592
Name = windows.storage.dll, Base = 0x76C70000, Top = 0x77235000, Size = 6049792
Name = profapi.dll, Base = 0x75B90000, Top = 0x75BA7000, Size = 94208
Name = powrprof.dll, Base = 0x759C0000, Top = 0x75A03000, Size = 274432
Name = UMPDC.dll, Base = 0x77A10000, Top = 0x77A1D000, Size = 53248
Name = kernel.appcore.dll, Base = 0x757C0000, Top = 0x757CF000, Size = 61440
Name = cryptsp.dll, Base = 0x75D10000, Top = 0x75D23000, Size = 77824
Name = WINSPOOL.DRV, Base = 0x67340000, Top = 0x673AB000, Size = 438272
Name = bcrypt.dll, Base = 0x77A40000, Top = 0x77A59000, Size = 102400
Name = PROPSYS.dll, Base = 0x67190000, Top = 0x67255000, Size = 806912
Name = IPHLPAPI.DLL, Base = 0x74E00000, Top = 0x74E32000, Size = 204800
Name = OLEAUT32.dll, Base = 0x776F0000, Top = 0x77782000, Size = 598016
Name = ole32.dll, Base = 0x77240000, Top = 0x77337000, Size = 1011712
Name = oledlg.dll, Base = 0x63590000, Top = 0x635BC000, Size = 180224
Name = urlmon.dll, Base = 0x73FC0000, Top = 0x7416B000, Size = 1748992
Name = iertutil.dll, Base = 0x728A0000, Top = 0x72AC9000, Size = 2265088
Name = gdiplus.dll, Base = 0x73E50000, Top = 0x73FB9000, Size = 1478656
Name = PSAPI.DLL, Base = 0x75A70000, Top = 0x75A76000, Size = 24576
Name = VERSION.dll, Base = 0x74DF0000, Top = 0x74DF8000, Size = 32768
Name = DINPUT8.dll, Base = 0x63550000, Top = 0x63587000, Size = 225280
Name = SensApi.dll, Base = 0x63540000, Top = 0x63548000, Size = 32768
Name = WININET.dll, Base = 0x72B00000, Top = 0x72F5C000, Size = 4571136
Name = inputhost.dll, Base = 0x66C70000, Top = 0x66D32000, Size = 794624
Name = wintypes.dll, Base = 0x71F10000, Top = 0x71FEA000, Size = 892928
Name = CoreMessaging.dll, Base = 0x72250000, Top = 0x722D9000, Size = 561152
Name = CoreUIComponents.dll, Base = 0x71FF0000, Top = 0x7224E000, Size = 2482176
Name = ntmarta.dll, Base = 0x745C0000, Top = 0x745E9000, Size = 167936
Name = WS2_32.dll, Base = 0x75690000, Top = 0x756EE000, Size = 385024
Name = dbghelp.dll, Base = 0x74380000, Top = 0x7450F000, Size = 1634304
Name = Syntconv.dll, Base = 0x10000000, Top = 0x10053000, Size = 339968
Name = MSVCP60.dll, Base = 0x634D0000, Top = 0x63540000, Size = 458752
Name = MFC42.DLL, Base = 0x633A0000, Top = 0x634C4000, Size = 1196032
Name = refs.dll, Base = 0x63200000, Top = 0x63396000, Size = 1662976
Name = OLEACC.dll, Base = 0x71770000, Top = 0x717C3000, Size = 339968
Name = UxTheme.dll, Base = 0x727F0000, Top = 0x7286A000, Size = 499712
Name = dwmapi.dll, Base = 0x666D0000, Top = 0x666F5000, Size = 151552
Name = MSCTF.dll, Base = 0x75A80000, Top = 0x75B83000, Size = 1060864
Name = clbcatq.dll, Base = 0x77540000, Top = 0x775C0000, Size = 524288
Name = ondemandconnroutehelper.dll, Base = 0x631E0000, Top = 0x631F2000, Size = 73728
Name = winhttp.dll, Base = 0x67280000, Top = 0x6733E000, Size = 778240
Name = ieframe.dll, Base = 0x62BE0000, Top = 0x631DA000, Size = 6266880
Name = NETAPI32.dll, Base = 0x62BC0000, Top = 0x62BD3000, Size = 77824
Name = WKSCLI.DLL, Base = 0x67160000, Top = 0x67170000, Size = 65536
Name = NETUTILS.DLL, Base = 0x67150000, Top = 0x6715B000, Size = 45056
Name = msIso.dll, Base = 0x62B70000, Top = 0x62BB3000, Size = 274432
Name = mswsock.dll, Base = 0x74690000, Top = 0x746E2000, Size = 335872
Name = NSI.dll, Base = 0x77790000, Top = 0x77797000, Size = 28672
Name = WINNSI.DLL, Base = 0x62B60000, Top = 0x62B68000, Size = 32768
Name = dataexchange.dll, Base = 0x64AB0000, Top = 0x64AE1000, Size = 200704
Name = dcomp.dll, Base = 0x64940000, Top = 0x64AA9000, Size = 1478656
Name = d3d11.dll, Base = 0x74750000, Top = 0x7492E000, Size = 1957888
Name = dxgi.dll, Base = 0x74950000, Top = 0x74A11000, Size = 790528
Name = dxcore.dll, Base = 0x74930000, Top = 0x74949000, Size = 102400
Name = twinapi.appcore.dll, Base = 0x66E40000, Top = 0x67024000, Size = 1982464
Name = RMCLIENT.dll, Base = 0x67130000, Top = 0x6714F000, Size = 126976
Name = sxs.dll, Base = 0x65530000, Top = 0x655B8000, Size = 557056
Name = DNSAPI.dll, Base = 0x745F0000, Top = 0x74681000, Size = 593920
Name = rasadhlp.dll, Base = 0x74570000, Top = 0x74578000, Size = 32768
Name = coml2.dll, Base = 0x75CB0000, Top = 0x75D0E000, Size = 385024
Name = msscript.ocx, Base = 0x62B40000, Top = 0x62B5C000, Size = 114688
Name = vbscript.dll, Base = 0x62AB0000, Top = 0x62B35000, Size = 544768
Name = amsi.dll, Base = 0x72690000, Top = 0x7269F000, Size = 61440
Name = USERENV.dll, Base = 0x74D30000, Top = 0x74D4E000, Size = 122880
Name = WLDP.DLL, Base = 0x62A80000, Top = 0x62AA2000, Size = 139264
Name = CRYPT32.dll, Base = 0x75BB0000, Top = 0x75CAB000, Size = 1028096
Name = MSASN1.dll, Base = 0x77600000, Top = 0x7760E000, Size = 57344
Name = WI**UST.dll, Base = 0x76340000, Top = 0x76386000, Size = 286720
Name = WindowsCodecs.dll, Base = 0x72370000, Top = 0x724D9000, Size = 1478656
Name = fwpuclnt.dll, Base = 0x74510000, Top = 0x74561000, Size = 331776
Name = TextInputFramework.dll, Base = 0x722E0000, Top = 0x72364000, Size = 540672
Name = MSHTML.dll, Base = 0x61790000, Top = 0x629D3000, Size = 19148800
Code Before:
8B C8 E8 6B D2 31 00 85 C0 75 04 33 D2 EB 0E 8B D0 8D 5A 01
Current Code:
8A 0A 42 84 C9 75 F9 2B D3 52 50 8D 4F 08 E8 6B B2 F7 FF 68
Call Stack:
00440ADE ===> 按键精灵2014.exe
Current Stack:
[0019DA94] = 6703C442
[0019DA98] = 5D9E3AF8
[0019DA9C] = 0019DC18
[0019DAA0] = 00000000
[0019DAA4] = 063E6D40
[0019DAA8] = 0019D974
[0019DAAC] = 00000107
[0019DAB0] = 00000000
[0019DAB4] = 0019D**
[0019DAB8] = 06476100
[0019DABC] = 063E6CC8
[0019DAC0] = 0019D974
[0019DAC4] = 00000107
[0019DAC8] = 00000000
[0019DACC] = 0019DC68
[0019DAD0] = 00000000
[0019DAD4] = 009E7390
[0019DAD8] = 063E6820
[0019DADC] = 063E5398
[0019DAE0] = 063EE5B8
[0019DAE4] = 063EB178
[0019DAE8] = 063E52E8
[0019DAEC] = 00000008
[0019DAF0] = 00000000
[0019DAF4] = 00000001
[0019DAF8] = 063EE5A8
[0019DAFC] = 063EB038
[0019DB00] = 00000000
[0019DB04] = 00000000
[0019DB08] = 00000000
[0019DB0C] = 00000000
[0019DB10] = 063E5890
[0019DB14] = 063EE7E8
[0019DB18] = 05A60000
[0019DB1C] = 00000004
[0019DB20] = 00000000
[0019DB24] = 0000003D
[0019DB28] = 0000003F
[0019DB2C] = 05A701C8
[0019DB30] = 063EE7E8
[0019DB34] = 063EE825
[0019DB38] = 063EE825
[0019DB3C] = 063EE825
[0019DB40] = 0019DAA4
[0019DB44] = 00000000
[0019DB48] = 0019DB68
[0019DB4C] = 77AAADEE
[0019D**] = 00000013
[0019DB54] = 00000000
[0019D**] = 0000000F
[0019DB5C] = 00000000
[0019DB60] = 00010001
[0019DB64] = 063EB068
[0019DB68] = 063E5428
[0019DB6C] = 00000008
[0019DB70] = 00000000
[0019DB74] = 00000001
[0019DB78] = 063E5A80
[0019DB7C] = 063EB088
[0019DB80] = 00000000
[0019DB84] = 00000000
[0019DB88] = 00000000
[0019DB8C] = 00000000
[0019DB90] = 009E7380
[0019DB94] = 063E32D0
[0019DB98] = 00408290
[0019DB9C] = 063E5A90
[0019DBA0] = 00000002
[0019DBA4] = 0000002D
[0019DBA8] = 0000002F
[0019DBAC] = 006BC0E7
[0019DBB0] = 063E32D0
[0019DBB4] = 063E32FD
[0019DBB8] = 063E32FD
[0019DBBC] = 063E32FD
[0019DBC0] = 0019DABC
[0019DBC4] = 00408400
[0019DBC8] = 063E5A90
[0019DBCC] = 00000002
[0019DBD0] = 00965B28
[0019DBD4] = 00000000
[0019DBD8] = 0000000F
[0019DBDC] = 063E52C0
[0019DBE0] = 00010001
[0019DBE4] = 0019DC10
[0019DBE8] = 063EE710
[0019DBEC] = 00965B28
[0019DBF0] = 00000000
[0019DBF4] = 6703C446
[0019DBF8] = 0000003D
[0019DBFC] = 0000003F
[0019DC00] = 0019DC18
[0019DC04] = 6703C442
[0019DC08] = 0019E0BC
[0019DC0C] = 008A1F25
[0019DC10] = 0000000A
[0019DC14] = 0019E0CC
[0019DC18] = 00440ADE
[0019DC1C] = 6703C476
[0019DC20] = 7552B000
[0019DC24] = 063EB0F8
[0019DC28] = 063E0FC0
[0019DC2C] = 02000002
[0019DC30] = 063E52C0
[0019DC34] = 00000001
[0019DC38] = 06474DC0
[0019DC3C] = 063E5EF0
[0019DC40] = 00000004
[0019DC44] = 00000011
[0019DC48] = 009E7390
[0019DC4C] = 06474DC0
[0019DC50] = 00000003
[0019DC54] = 00000003
[0019DC58] = 00000011
[0019DC5C] = 009E7390
[0019DC60] = 06474B68
[0019DC64] = 009E7390
[0019DC68] = 06452B80
[0019DC6C] = 063EDFB8
[0019DC70] = 00000002
[0019DC74] = 0119DCA4
[0019DC78] = 06452B68
[0019DC7C] = 1600091F
[0019DC80] = 00000010
[0019DC84] = 00000001
[0019DC88] = 00000011
[0019DC8C] = 05A60270
[0019DC90] = 05A60000
[0019DC94] = 05A6C298
[0019DC98] = 0000000C
[0019DC9C] = 05A60270
[0019DCA0] = 05A60000
[0019DCA4] = 02000002
[0019DCA8] = 05A60000
[0019DCAC] = 064538E8
[0019DCB0] = 06452B70
[0019DCB4] = 02000002
[0019DCB8] = 00000000
[0019DCBC] = 05A60000
[0019DCC0] = 77ACB783
[0019DCC4] = 0000000C
[0019DCC8] = 0019DDA8
[0019DCCC] = 77AAE780
[0019DCD0] = 00000001
[0019DCD4] = 064538F0
[0019DCD8] = 0000000C
[0019DCDC] = 77AAE9F9
[0019DCE0] = A2F30894
[0019DCE4] = 064538E8
[0019DCE8] = 05A60000
[0019DCEC] = 00000000
[0019DCF0] = 23010022
[0019DCF4] = 00000002
[0019DCF8] = 7FFA0002
[0019DCFC] = 00000031
[0019DD00] = 00000000
[0019DD04] = 05A60000
[0019DD08] = 00000011
[0019DD0C] = 06452B80
[0019DD10] = 00000011
[0019DD14] = 05A60000
[0019DD18] = 0000000C
[0019DD1C] = 01473710
[0019DD20] = 0000000C
[0019DD24] = 62D5BE9F
[0019DD28] = 015196D8
[0019DD2C] = 01519818
[0019DD30] = 62D95B20
[0019DD34] = 0019DD4C
[0019DD38] = 064538E8
[0019DD3C] = 015196B8
[0019DD40] = 00000001
[0019DD44] = 015196B8
[0019DD48] = 00000000
[0019DD4C] = 05A602D4
[0019DD50] = 00000001
[0019DD54] = 00000000
[0019DD58] = 0150E1A8
[0019DD5C] = 01470011
[0019DD60] = 11000011
[0019DD64] = 015196D8
[0019DD68] = 62BE8AE0
[0019DD6C] = 0000000C
[0019DD70] = 015196D4
[0019DD74] = 00000000
[0019DD78] = 01010064
[0019DD7C] = 06453948
[0019DD80] = 014F0000
[0019DD84] = 00000000
[0019DD88] = 0000000C
[0019DD8C] = 01010002
[0019DD90] = 0150DEB8
[0019DD94] = 0150E1A8
[0019DD98] = 0019DED0
[0019DD9C] = 77AE9F80
[0019DDA0] = D55D8C0C
[0019DDA4] = FFFFFFFE
[0019DDA8] = 0019DE04
[0019DDAC] = 77AF6CDB
[0019DDB0] = 00000000
|
|